Home > Today’s Crypto News
bitcoin
bitcoin

$93113.538616 USD

-0.11%

ethereum
ethereum

$1748.590950 USD

-2.15%

tether
tether

$1.000392 USD

0.02%

xrp
xrp

$2.177851 USD

-1.16%

bnb
bnb

$600.317897 USD

-0.84%

solana
solana

$151.339663 USD

1.47%

usd-coin
usd-coin

$0.999927 USD

0.01%

dogecoin
dogecoin

$0.179240 USD

2.45%

cardano
cardano

$0.707230 USD

2.73%

tron
tron

$0.243466 USD

-0.61%

sui
sui

$3.323843 USD

10.76%

chainlink
chainlink

$14.828095 USD

0.41%

avalanche
avalanche

$21.905207 USD

-0.82%

stellar
stellar

$0.275988 USD

4.91%

unus-sed-leo
unus-sed-leo

$9.206268 USD

0.44%

Oracle Manipulation

Oracle manipulation, or oracle price manipulation, is an exploit most common in the DeFi space where an oracle smart contract is manipulated by attackers, which leads to system failure, theft and other damages. DeFi networks are reported to have lost over $33 million due to price oracle manipulation in 2020 alone.

Oracles are third-party service providers that supply blockchains with external or real-world data such as price feeds, weather information, statistics, etc. Price feeds are by far the most exploited oracle data since they allow attackers to steal millions of funds from DeFi platforms. 

Generally, there are two ways an oracle can gather price information. One is to seamlessly siphon price data from centralized exchanges via APIs. On the other hand, oracles can also do the calculations themselves by consulting decentralized exchanges (DEXs). Both methods have their own sets of advantages and disadvantages, as well as ways of being manipulated.

In the Harvest Finance hack, the culprit was able to penetrate its pools through a flash loan using a form of oracle manipulation. Basically, the hacker reduced the value of USDC within the Curve pool via a trade. Then, the perpetrator got into the Harvest pool at the deflated price, brought USDC back to its initial price reversing his trade, then exited the pool at a much higher price.